PASTA is a seven-step threat modeling methodology that helps teams understand how an application could be attacked and what that would mean for a business. Short for Process for Attack Simulation and Threat Analysis, it links technical weaknesses to business impact, helping teams prioritize the risks that matter most.
VerSprite CEO, Tony UcedaVélez, and security leader Marco M. Morana co-created PASTA in 2015 to close gaps left by earlier threat modeling frameworks. It scales up or down to fit organizations of different sizes, and most other threat modeling methodologies can map into it.
What is PASTA threat modeling?
PASTA connects how an application works with what the business needs to protect. For an online retailer, that could mean protecting customer data, preventing fraudulent purchases, and keeping checkout available.
Business leaders help establish those priorities, while engineering and security teams examine the systems, dependencies, and safeguards that support them. Compliance requirements are considered alongside these goals. That context helps teams assess technical weaknesses in practical terms.
Could a gap in access controls let one customer view another’s order details? Could an attacker manipulate a discount to buy goods at a price below the intended price? Each scenario connects a technical issue to a business consequence, such as a privacy breach or financial loss.
Teams use evidence, like relevant threat intelligence, vulnerability findings, and attack simulations, to assess how likely those scenarios are and whether existing safeguards would hold up. The goal is to give the business a clear basis for deciding which risks to address first and why.
Benefits of using PASTA
- Collaborative: aligns security efforts with business objectives, tailoring security measures to protect critical assets and letting departments leverage existing organizational processes.
- Customizable: scales up or down to fit specific industry needs and different types of projects.
- Risk-centric: prioritizes threats by their potential impact on business operations and assets.
- Evidence-based: supports threat motives and leverages data instead of guesswork.
- Attacker-focused: centers on probability of attack, likelihood, inherent risk, and impact of compromise, incorporating simulated real-world attack scenarios for a more realistic threat assessment.
PASTA Threat Modeling Steps
PASTA consists of seven distinct phases:
The seven stages of PASTA threat modeling
- Define objectives. Establish what the business needs to protect, including security and compliance requirements. For an online retailer, priorities might include preventing fraudulent purchases, protecting customer information, and keeping checkout available.
- Define technical scope. Identify the application, infrastructure, and dependencies included in the assessment. This could cover the storefront, checkout service, customer database, and integration with a payment provider.
- Application decomposition. Map how the system works, including data flows, access controls, and trust boundaries. This could trace how an order moves from the customer’s browser through checkout to the payment provider, noting where data crosses between systems with different levels of trust.
- Threat analysis. Identify relevant threats using threat intelligence, known attacks, and information about the system. For example, investigate whether account takeover or automated payment fraud presents a credible threat to the retailer.
- Vulnerability and weakness analysis. Examine weaknesses in the design and implementation using CVSS scores and CWEs, and connect them to the identified threats. For example, check whether missing authorization checks could let a customer access or change another customer’s order.
- Attack modeling. Develop and evaluate attack scenarios, using techniques such as attack trees and attack simulation. For example, model how an attacker might take over a customer account and place fraudulent orders, then test the relevant safeguards in an authorized environment.
- Risk and impact analysis. Assess likely business consequences, prioritize mitigations, and determine what risk remains. For example, a retailer might weigh potential fraud losses or customer data exposure against the effectiveness and cost of proposed safeguards.
Because of its risk-centricity and comprehensive seven-step process, PASTA captures not just technical scope and possible vulnerabilities, but the compliance and regulatory needs of an organization. This produces a risk- and asset-centric output, giving teams a practical way to prioritize security requirements and mitigations.
For a deeper walkthrough of each step, VerSprite (PASTA's creator) publishes its own guide: PASTA Threat Modeling Process.
How is PASTA implemented?
PASTA can be incorporated into agile and DevOps workflows by focusing an assessment on a specific application, feature, or significant change. Business stakeholders define what needs protecting and the potential consequences of an attack. Security and engineering teams then examine the system, assess threats, and agree on safeguards.
Teams can revisit the relevant parts of the assessment as designs, dependencies, or threats change, and track agreed mitigations in their development backlog.
Are there any limitations to PASTA?
- Time and expertise required: PASTA’s seven stages involve gathering threat intelligence, analyzing weaknesses, and evaluating attack scenarios. Doing this thoroughly takes specialist input and coordination across business, engineering, and security teams. Teams with limited resources may need to start with a tightly scoped application or feature to keep the assessment manageable.
- Reliance on available data: its accuracy and effectiveness depend on the availability and quality of data about the system and its architecture.
- Scalability at extremes: while PASTA is designed to scale, extremely large or distributed systems can pose additional challenges for a thorough analysis.
- Limited mitigation guidance: PASTA is strong on analysis but offers comparatively limited direction on mitigation strategies, so organizations without in-house expertise may need outside help to act on the findings.
Where tooling helps
PASTA's later stages produce the most value and take the most effort. Threat modeling platforms, like ThreatModeler Nexus, automate the heavy lifting with:
Scoring that reflects business impact. PASTA's final stage ties technical findings to business risk. ThreatModeler Nexus scores every threat on likelihood and impact using inputs you set: whether a component is a high-value target, the business risk the system carries, and whether it faces the outside world.
Attack paths and weakness mapping. Stages five and six ask how an attacker would move through a system and which weaknesses they would use. ThreatModeler Nexus maps threats to MITRE ATT&CK techniques and CWE entries, so the analysis connects to the same references used in threat intelligence and design reviews.
Mitigation guidance the methodology leaves open. PASTA identifies risk, but offers limited direction on what to implement. ThreatModeler Nexus pairs each threat with the security requirements that address it and exports them to your issue tracker as actionable work items.
Should I consider other threat modeling methodologies?
PASTA is one of several established threat modeling methodologies, alongside frameworks like STRIDE, OCTAVE, and VAST. To compare approaches, see Threat Modeling Methodologies.
Frequently asked questions
During which stage of the PASTA framework is an attack tree created?
The attack tree is created during the sixth stage, attack modeling. It helps identify potential threats, visualizes attack paths, and supports prioritization of security measures, offering a structured way to prevent a threat actor from achieving their goals against a given asset or target.
What are the benefits of using PASTA in risk management?
PASTA aligns security efforts with business objectives, gives risk-centric prioritization based on real-world attack scenarios, and supports evidence-based decisions grounded in data rather than assumptions, helping organizations focus mitigation effort on what actually matters to the business.
How does PASTA compare to other threat modeling methodologies?
Unlike approaches such as STRIDE, which focus primarily on technical threat categories, PASTA is risk-centric and business-driven, walking through seven stages that connect technical vulnerabilities back to business objectives and impact.
What types of organizations benefit most from PASTA?
PASTA suits organizations that need to tie technical risk directly to business impact, particularly where compliance and regulatory requirements are a major driver, such as financial services, healthcare, and federal organizations.
PASTA is a risk-centric, 7-step threat modeling methodology that ties technical risk to business impact and compliance.




